Getting Data In

How can I omit the timestamp and host that splunk automatically add to my logs

dadi
Path Finder

hi guys,
I've added my first logs in splunk today. I notice that in the beginning of each row splunk has added a prefix of timestamp and host. For example this is a single log line(refer to the bold text):

Jun 29 16:16:44 127.0.0.1 2011-06-29 16:16:44.067 [main ] INFO com.cloudon.VabConnector - About to activate VabConnector with parameters node id [1], ZK_connect_str[127.0.0.1:2181], VabConnectionServerPort[8000], ownIp[10.0.0.8]

I've configured my channel in the web interface in - Home » Add Data » UDP » Add New

I've defined it as syslog source type and I'm sending the logs from my application. I've used wireshark to verify that the message I send is without the prefix.

Do you know why splunk add this prefix?

More importantly, I can I remove it from the logs?

Thanks,
Eldad.

Tags (1)
0 Karma
1 Solution

dadi
Path Finder

I found the answer in here

View solution in original post

0 Karma

dadi
Path Finder

I found the answer in here

0 Karma
Get Updates on the Splunk Community!

ATTENTION!! We’re MOVING (not really)

Hey, all! In an effort to keep this Slack workspace secure and also to make our new members' experience easy, ...

Splunk Admins: Build a Smarter Stack with These Must-See .conf25 Sessions

  Whether you're running a complex Splunk deployment or just getting your bearings as a new admin, .conf25 ...

AppDynamics Summer Webinars

This summer, our mighty AppDynamics team is cooking up some delicious content on YouTube Live to satiate your ...